> TODAY'S SUMMARY (34 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A significant zero-day vulnerability (CVE-2026-88) in Citrix NetScaler has been actively exploited, prompting urgent updates for affected systems. Similarly, the Rejetto HFS flaw (CVE-2026-61500) is being targeted, allowing attackers to gain administrative access and execute remote code. In the realm of healthcare, a bipartisan bill has been passed to strengthen cybersecurity measures, following over 730 breaches affecting hundreds of millions of Americans last year. On the AI front, Google has paused its open-source bug bounty program due to a surge in invalid, AI-generated vulnerability reports. Additionally, recent arrests connected to cybercrime groups like ShinyHunters signal ongoing efforts to combat organized hacking networks.
|
// AI-powered summary generated at 12:00
Today, I published the following diary on isc.sans.edu: “macOS: Who’s Behind This Network Connection?“: When you must investigate suspicious behavior or work on an actual incident, you could be asked to determine who’s behind a network connection. From a pure network point of view, your firewall or...
Une attaque massive de ransomware a touché le domaine de messagerie gouvernemental "gov.lk" du Sri Lanka, entraînant la perte de données du 17 mai au 26 août 2023. L'agence de technologie de l'information et de la communication (ICTA) a confirmé que le virus aurait pu affecter environ 5 000 adresses...
Le Western Washington Medical Group a signalé une violation de données affectant jusqu'à 350 863 patients, impliquant un incident de piratage/IT sans plus de détails disponibles pour le moment.
Nearly one in three young adults has had their personal information misused
Vulnerability could be exploited to gain elevated privileges
Today, I published the following diary on isc.sans.edu: “Python Malware Using Postgresql for C2 Communications“: For modern malware, having access to its C2 (Command and control) is a crucial point. There are many ways to connect to a C2 server using tons of protocols, but today, HTTP remains very c...
Feds warn that patching will not rid system of APT group
QuiteRAT, the North-Korea-Backed group’s new malware, exploits a 2022 ManageEngine ServiceDesk vulnerability
Le directeur d'école Hannes Sauerzopf explique dans un entretien avec NÖN que rien ne fonctionnait, du téléphone à l'ordinateur. Tout était crypté, donc ils ont débranché immédiatement et fait appel à trois entreprises externes pour analyser la situation et restaurer l'infrastructure numérique d'ici...
Threat actors use unique infection chains to deploy QakBot malware
L'Université Carnegie Mellon a été victime d'une cyberattaque le 25 août 2023, qui a potentiellement compromis les informations personnelles de plus de 7 300 personnes, incluant des étudiants actuels ou anciens, des employés, des candidats et des contractants. L'attaque a été rapidement détectée par...
Between Monday and Tuesday, the FBI has traced approximately 1580 stolen Bitcoins
The compromised data includes names, usernames, email addresses and internal service-related details
L'école spécialisée Astrid-Lindgren-Schule à Lemgo a été victime d'une cyberattaque qui a toujours des conséquences. Les systèmes de téléphone et d'e-mail de l'école ne fonctionnent toujours pas. Des experts travaillent actuellement à restaurer les données qui ont été cryptées lors de l'attaque. Ini...
Netenrich suggested LOLKEK, BIT, OBZ, U2K and TZW ransomware strains share significant similarities
The draft standards are expected to become the global benchmark for quantum-resistant cybersecurity across the world in 2024
La clinique TissuPath a envoyé une lettre de notification à tous les médecins référents principaux concernant l'incident et est en train de contacter toutes les personnes affectées. Le Centre de cybersécurité australien (Australian Cyber Security Centre - ACSC) de l'Australian Signals Directorate es...
The data breach is suspected to be linked to the Clop MOVEit hack
Emails use social engineering to con victims
Les Stadtwerke Neumünster (SWN) en Allemagne ont été victimes d'une cyberattaque de type espionnage, ce qui les a conduits à mettre hors ligne tous leurs systèmes informatiques par mesure de précaution. Bien que les services essentiels tels que l'électricité, le gaz, le chauffage et l'internet reste...